When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

zetlyn/cve-nvd vulnerability cve CVE-2025-1942 cpe cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* known 2025-03-04

https://nvd.nist.gov/vuln/detail/CVE-2025-1942

Properties

cvss9.8
receipt
Source
NVD
Its words
9.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "43A02EBD-58CF-4057-A3D7-3828B599D954",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136."
      },
      {
        "lang": "es",
        "value": "Cuando String.toUpperCase() hacía que una cadena se hiciera más larga, era posible que la memoria no inicializada se incorporara a la cadena de resultado. Esta vulnerabilidad afecta a Firefox < 136 y Thunderbird < 136."
      }
    ],
    "id": "CVE-2025-1942",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-1942",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-25T14:08:58.588635Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-04T14:15:39.167",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1947139"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-908"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
productFirefox
receipt
Source
NVD
Its words
Firefox
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "43A02EBD-58CF-4057-A3D7-3828B599D954",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136."
      },
      {
        "lang": "es",
        "value": "Cuando String.toUpperCase() hacía que una cadena se hiciera más larga, era posible que la memoria no inicializada se incorporara a la cadena de resultado. Esta vulnerabilidad afecta a Firefox < 136 y Thunderbird < 136."
      }
    ],
    "id": "CVE-2025-1942",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-1942",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-25T14:08:58.588635Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-04T14:15:39.167",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1947139"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-908"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
statusModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "43A02EBD-58CF-4057-A3D7-3828B599D954",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136."
      },
      {
        "lang": "es",
        "value": "Cuando String.toUpperCase() hacía que una cadena se hiciera más larga, era posible que la memoria no inicializada se incorporara a la cadena de resultado. Esta vulnerabilidad afecta a Firefox < 136 y Thunderbird < 136."
      }
    ],
    "id": "CVE-2025-1942",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-1942",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-25T14:08:58.588635Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-04T14:15:39.167",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1947139"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-908"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
vendorMozilla
receipt
Source
NVD
Its words
Mozilla
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "136",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DB4CDD0-EC54-43D0-ACB2-F159ABA53D2C",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "43A02EBD-58CF-4057-A3D7-3828B599D954",
                "versionEndExcluding": "136.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136."
      },
      {
        "lang": "es",
        "value": "Cuando String.toUpperCase() hacía que una cadena se hiciera más larga, era posible que la memoria no inicializada se incorporara a la cadena de resultado. Esta vulnerabilidad afecta a Firefox < 136 y Thunderbird < 136."
      }
    ],
    "id": "CVE-2025-1942",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-1942",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-25T14:08:58.588635Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-04T14:15:39.167",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1947139"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-14/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-17/"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-908"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}

Text

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136. Cuando String.toUpperCase() hacía que una cadena se hiciera más larga, era posible que la memoria no inicializada se incorporara a la cadena de resultado. Esta vulnerabilidad afecta a Firefox < 136 y Thunderbird < 136.